MEDIUM6.1
GHSA-4c5w-qqfg-grf3
Symphony CMS XSS Vulnerabilities
Quick fix
GHSA-4c5w-qqfg-grf3 — symphonycms/symphony-2: upgrade to the fixed version with the command below.
composer require symphonycms/symphony-2:^2.6.4Details
Multiple cross-site scripting (XSS) vulnerabilities in `content/content.systempreferences.php` in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) `email_sendmail[from_name]`, (2) `email_sendmail[from_address]`, (3) `email_smtp[from_name]`, (4) `email_smtp[from_address]`, (5) `email_smtp[host]`, (6) `email_smtp[port]`, (7) `jit_image_manipulation[trusted_external_sites]`, or (8) `maintenance_mode[ip_whitelist]` parameters to system/preferences.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symphonycms/symphony-2
Introduced in:
0Fixed in: 2.6.4Fix
composer require symphonycms/symphony-2:^2.6.4References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8766[ADVISORY]
- https://github.com/symphonycms/symphony-2/commit/651e150091c61fb60ad1dff2bc2166185a83d9d6[WEB]
- https://github.com/symphonycms/symphony-2[PACKAGE]
- https://web.archive.org/web/20210321090853/https://cybersecurityworks.com/zerodays/cve-2015-8766-getsymphoney.html[WEB]
- http://seclists.org/fulldisclosure/2015/Dec/60[WEB]
- http://www.getsymphony.com/download/releases/version/2.6.4[WEB]